@maltrail found tdesktop[.]telega[.]one resolve as malicious.
- https://t.co/4Y6HvO97si - R-Vision page about Telegram Desktop app, information about this domain as legitimate.
- https://t.co/obPmck37Cj
Maybe false-positive?
🔥 New open-source #Suricata rules 🔥
https://t.co/oELvuKfAoP
For over a year now I’ve been sharing interesting #malware findings in network traffic here!
Today I want to share our project PT Rules🎉
(there are many rules written for the threats I indicated in my tweets below⬇️)
🔓 After some days brought idea to life.
Created #HomuWitch Ransomware #decryptor.
You can easily decrypt this #ransomware using this tool.
Used C#, .NET, VS, ICSharpCode library, some time and some coffee to do it.
https://t.co/qfjqxxc3iW
Found old #kazy#botnet with simple #cryptor (TripleDES and gzip). Encryption key and IV with malware payload stored in .NET resources. Can be easily decrypted using CyberChef 😎. Also there is builder sample in vx-underground awesome builders collection 💪.